Live data from Hacker News

Why Apple's iPhone encryption won't stop NSA

siliconexposed.blogspot.com

21–30 of 71 posts

Re: Why Apple's iPhone encryption won't stop NSA

#21
Friendly reminder: don't embed images from other people's websites, especially if you're looking to get on HN/Slashdot/reddit/whatever.

First, it's rude. The owner of the second website has to deal with the burden of hosting traffic on your site and gets nothing in return. In this case, the blog kept downloading an image from siliconpr0n.org, effectively DoSing the website and taking it offline. Horrible. Hopefully tomorrow everything is back to normal and the owner of siliconpr0n.org isn't stuck with a massive bill from his host.

Second, there's no guarantee the image will stay online. Maybe the directory structure on the site will get reorganized or something. Maybe the website will go offline for good, only to get picked up by a domain squatter. Maybe the owner of the website will decide to change the direct-linked image to something else you weren't expecting. You have no idea.

Re: Why Apple's iPhone encryption won't stop NSA

#22
post #16
post #14

Earlier quoted context omitted.

> I think the crux of the matter is that this crypto scheme is not designed to stop the NSA I think the NSA has so many tools available when it comes to hack into people's data, it doesn't really matter how you secure yourself, there are many ways for the NSA to spy on people if they really want to. Right now I don't think anyone can really pretend to secure their data from the NSA. It might make it harder for them,…

Airgaps and secured physical access are probably good enough.

[deleted]

Re: Why Apple's iPhone encryption won't stop NSA

#24
post #9

MitM with a 0-day payload? Acid etching and SEM? You would have to be an extremely high-value target to legitimately worry about this stuff. The post is attacking a straw man. Apple's iPhone security is meant to address criminals, mass surveillance, and overzealous law enforcement. They're not claiming a single phone will withstand the entire resources of the NSA devoted to breaking it.

> The post is attacking a straw man.

It's a straw man, but not his straw man. Pull up popular press articles about iOS8's disk encryption and you'll find that a disturbing number of them uncritically claim that it's meant to thwart the NSA. It's been driving me crazy.

Re: Why Apple's iPhone encryption won't stop NSA

#25

Friendly reminder: don't embed images from other people's websites, especially if you're looking to get on HN/Slashdot/reddit/whatever. First, it's rude. The owner of the second website has to deal with the burden of hosting traffic on your site and gets nothing in return. In this case, the blog kept downloading an image from siliconpr0n.org, effectively DoSing the website and taking it offline. Horrible. Hopefully t…

You're assuming I'm not affiliated with siliconpr0n.

I'm actually one of the main contributors to the site and took a lot of the photos on it, just not that particular one. John (my friend who actually admins the server) is fully aware of the situation and just raised the resource limits to counter the DoS. If either of us uses an image somewhere that we expect to stay online for a while, we make a point of leaving it in place when reorganizing directory structures etc.

Re: Why Apple's iPhone encryption won't stop NSA

#26
post #4

I'd like for people to start thinking about security measures, including encryption, as a cost function rather than as a boolean condition (e.g. safe vs. unsafe; stop the NSA vs. not stop the NSA). I doubt there is anyone who can stop the NSA from executing a targeted attack that breaches that information. My feeling is that good security measures increase the marginal cost per person surveilled. As the article point…

Disk encryption will only stop a targeted attack (someone physically gets their hands on your phone) anyway. All this does is raise the cost by a bit.

Re: Why Apple's iPhone encryption won't stop NSA

#27
If you look at the incentives for Apple in this scenario: It's best for them if we all think their phones are secure. And it's also best for them if they dont piss off LEO. So the rational thing for them to do, is convince us all they have strongly encrypted their phones, while continuing to provide some type of back door, but hiding it well. Parallel contruction etc etc

Re: Why Apple's iPhone encryption won't stop NSA

#28
post #3

I'm sorry, but this is just plain wrong. Let's take "since the key is physically burned in"... You don't need to burn it in, it could easily be stored in a few bytes of on-die sram. As for the assertion that a de-powered chip can't wipe itself? You can just go out and buy a self wiping chip ... you don't need to be either Apple or the NSA, just have a credit card.

If the key is kept across a battery replacement or repair procedure, then it's going to be hard-wired/fused into the chip. SRAM needs to be powered constantly to retain data.

Credit cards/smartcards include self-destructs that will erase the nonvolatile memory (flash) in certain cases if power is applied while a tamper signal is asserted. They cannot erase data while in the "off" state. One of the problems with fuse-based memory is that it's easier to dump off the silicon than, say, Flash.

Although I haven't decapped an A7 yet (as soon as I get my hands on one, rest assured I will) adding flash to an IC fab process is very expensive and adds somewhere around a dozen new masks, so OTP fuse memory (which doesn't need any new masks) is typically used instead of flash for on-die ID codes etc.

Re: Why Apple's iPhone encryption won't stop NSA

#29
post #4

I'd like for people to start thinking about security measures, including encryption, as a cost function rather than as a boolean condition (e.g. safe vs. unsafe; stop the NSA vs. not stop the NSA). I doubt there is anyone who can stop the NSA from executing a targeted attack that breaches that information. My feeling is that good security measures increase the marginal cost per person surveilled. As the article point…

Rising the cost hurts the population much more in the long run - we, the people, we pay the surveillance for us. No one else. We must fight hard that we don't need to pay that tax any more - money which flows in large sums directly to the military/industrial complex.

Those intelligence budgets aren't going to get smaller, almost no matter what. The general US population has no idea how much is spent, their best guess would be: a lot (and it'd be a correct one); so there can't hardly even be a voter push-back based on expenditures.

As such, the best option is to make it so expensive to carry out mass surveillance, their only choice is to be selective about who they target and to focus on specific individuals rather than a billion people in general.

The cost should be drastically increased in all regards: time, electricity, water, monetary, etc.

It's very likely this will happen. The NSA was sitting at the ultimate sweet-spot in history, but windows like that are only open for extremely brief amounts of time. It will close and there is nothing that the NSA can do to stop it.

Re: Why Apple's iPhone encryption won't stop NSA

#30
post #24
post #9

MitM with a 0-day payload? Acid etching and SEM? You would have to be an extremely high-value target to legitimately worry about this stuff. The post is attacking a straw man. Apple's iPhone security is meant to address criminals, mass surveillance, and overzealous law enforcement. They're not claiming a single phone will withstand the entire resources of the NSA devoted to breaking it.

> The post is attacking a straw man. It's a straw man, but not his straw man. Pull up popular press articles about iOS8's disk encryption and you'll find that a disturbing number of them uncritically claim that it's meant to thwart the NSA. It's been driving me crazy.

Exactly. I wrote it to set the record straight: Apple's crypto is intended to guard against a limited class of attacks, and "the KGB is after me" is not one of them.
Post reply on HN